DNSCrypt is a protocol that encrypts, authenticates and optionally anonymizes communications between a DNS client and a DNS resolver. It prevents DNS spoofing. It uses cryptographic signatures to verify that responses originate from the chosen DNS resolver and haven’t been tampered with.

It is an open specification, with free and open source reference implementations, and it is not affiliated with any company nor organization.

Free, DNSCrypt-enabled resolvers are available all over the world.

Source: dnscrypt.info/

Our DNSCrypt server is behind Unbound which includes DNSSEC.

It also supports Anonymized DNS.
And of course, no logs enabled.

Install on your device

Follow the link and select your operating system.


Config file


Change your dnscrypt-proxy.toml config file.
server_names = ['pwoss.org-dnscrypt']`


Anonymized DNS

Go to the bottom routes = [ and add:

routes = [
    { server_name='pwoss.org-dnscrypt', via=['anon-pwoss.org'] }


Restart the service or reconnect your client.

Check your connection with dnsleaktest.com.